Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 58268cb4217f61ce…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 611f8aa02465054c9f18f6bb6990188c SHA-1: cc451484dac230d3aa33e76225efcc767db8210c SHA-256: 58268cb4217f61ce59cbd47ca1a4b2666e5fd2797326e2c0a619bf51d1eecedc
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary attack pattern is likely spearphishing attachment, where the user is tricked into opening the malicious Excel file. The file's purpose is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0